Vulnerability Description
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prasathmani | Tiny File Manager | <= 2.4.7 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/166330/Tiny-File-Manager-2.4.6-Shell-UploadExploitThird Party AdvisoryVDB Entry
- https://febin0x4e4a.wordpress.com/2022/01/23/tiny-file-manager-authenticated-rcePatchThird Party Advisory
- https://github.com/febinrev/tinyfilemanager-2.4.3-exploit/raw/main/exploit.shExploitThird Party Advisory
- https://github.com/prasathmani/tinyfilemanager/commit/2046bbde72ed76af0cfdcae082PatchThird Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636PatchThird Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636/files/a93fc321a3c89fdb9bPatchThird Party Advisory
- https://raw.githubusercontent.com/febinrev/tinyfilemanager-2.4.6-exploit/main/exExploitThird Party Advisory
- https://sploitus.com/exploit?id=1337DAY-ID-37364&utm_source=rss&utm_medium=rssExploitThird Party Advisory
- http://packetstormsecurity.com/files/166330/Tiny-File-Manager-2.4.6-Shell-UploadExploitThird Party AdvisoryVDB Entry
- https://febin0x4e4a.wordpress.com/2022/01/23/tiny-file-manager-authenticated-rcePatchThird Party Advisory
- https://github.com/febinrev/tinyfilemanager-2.4.3-exploit/raw/main/exploit.shExploitThird Party Advisory
- https://github.com/prasathmani/tinyfilemanager/commit/2046bbde72ed76af0cfdcae082PatchThird Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636PatchThird Party Advisory
- https://github.com/prasathmani/tinyfilemanager/pull/636/files/a93fc321a3c89fdb9bPatchThird Party Advisory
- https://raw.githubusercontent.com/febinrev/tinyfilemanager-2.4.6-exploit/main/exExploitThird Party Advisory
FAQ
What is CVE-2021-45010?
CVE-2021-45010 is a vulnerability with a CVSS score of 8.8 (HIGH). A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP file...
How severe is CVE-2021-45010?
CVE-2021-45010 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-45010?
Check the references section above for vendor advisories and patch information. Affected products include: Prasathmani Tiny File Manager.